> ## Documentation Index
> Fetch the complete documentation index at: https://docs.iru.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Single Sign-On with Google Workspace (SAML)

> Configure SAML-based SSO between Google Workspace and Iru Endpoint. Set up the SAML app in Google Admin Console and map user attributes for login.

### About Google Workspace SAML Integration

Google Workspace SAML integration in Iru Endpoint lets you set up SAML-based SSO integration with Google Workspace for users accessing Iru Endpoint through their Google Workspace credentials.

#### How It Works

When users attempt to access Iru Endpoint, they're redirected to Google Workspace for authentication. After successful authentication, Google Workspace sends a SAML assertion back to Iru Endpoint, which validates the user's identity and grants access. SSO can be used for [Iru Endpoint Web App](/en/endpoint/getting-started/foundation/admins-and-access) sign-in and for [Require Authentication with Automated Device Enrollment](/en/endpoint/enrollment/configure-require-authentication-for-enrollment).

<Tabs>
  <Tab title="Iru Web App Configuration">
    ### Setting Up the SAML Connection

    <Note>
      You'll need to complete the initial setup in Iru Endpoint first to get the configuration information required for Google Workspace. After copying the Entity ID and ACS URL, switch to the [**Google Workspace Configuration**](#google-workspace-configuration) tab and continue with [**Configuring Google Workspace Application**](#configuring-google-workspace-application).
    </Note>

    <Steps>
      <Step title="Navigate to the Account Menu Button">
        In Iru Endpoint, in the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu).
      </Step>

      <Step title="Access Authentication Settings">
        Click the **Access** option in the menu.

        <Frame>
          <img src="https://mintcdn.com/iru/8BYPjuKZa-zyEEf_/assets/media/images/iru-nav-access.png?fit=max&auto=format&n=8BYPjuKZa-zyEEf_&q=85&s=466fdf5fb47efd6bab8b450a5a1e8302" alt="Screenshot of the account menu with Access option highlighted" width="562" height="1040" data-path="assets/media/images/iru-nav-access.png" />
        </Frame>
      </Step>

      <Step title="Select Admin and Authentication">
        Select the **Admin and authentication** tab (selected by default) and scroll down to **Authentication methods**.
      </Step>

      <Step title="Add Authentication Method">
        Click **+ Authentication method**.
      </Step>

      <Step title="Enter Display Name">
        Enter a display name for the SSO Connection.
      </Step>

      <Step title="Select Authentication Method">
        Select **SAML** for the Authentication method.
      </Step>

      <Step title="Create Connection">
        Click **Create**.
      </Step>

      <Step title="Configuration Information">
        Click **Configuration information** if that section is not already expanded.
      </Step>

      <Step title="Copy Service Provider Entity ID">
        Copy the **Service provider entity ID** into a text document for later use. You'll need this for the Google Workspace configuration.
      </Step>

      <Step title="Copy ACS URL">
        Copy the **Assertion consumer service (ACS) URL** into a text document for later use. You'll need this for the Google Workspace configuration.

        <Frame>
          <img src="https://mintcdn.com/iru/Qq59wQ8jCPy0XJe9/assets/media/images/iru-support-google-saml_11-08-26.png?fit=max&auto=format&n=Qq59wQ8jCPy0XJe9&q=85&s=7d56d5b22f71fb05dd59c83555c02430" alt="Configuration Information, Service provider entity ID, and Assertion consumer service (ACS) URL" width="2166" height="940" data-path="assets/media/images/iru-support-google-saml_11-08-26.png" />
        </Frame>
      </Step>

      <Step title="Keep Tab Open">
        Keep the Iru Endpoint configuration modal open, then switch to the [**Google Workspace Configuration**](#google-workspace-configuration) tab to continue with [**Configuring Google Workspace Application**](#configuring-google-workspace-application).
      </Step>
    </Steps>

    ### Configuring Iru Endpoint SAML Connection

    <Note>
      After completing the Google Workspace configuration, return here to finish [**Configuring Iru Endpoint SAML Connection**](#configuring-iru-endpoint-saml-connection) in Iru Endpoint. You'll need the SSO URL, Entity ID, and certificate from Google Workspace.
    </Note>

    <Steps>
      <Step title="Return to Iru Endpoint">
        Go back to the Custom SAML modal in Iru Endpoint.
      </Step>

      <Step title="User Matching">
        Scroll down to **User Matching** section.
      </Step>

      <Step title="Set IdP Attribute">
        Set **IdP attribute** to **Attribute**.
      </Step>

      <Step title="Set Attribute Name">
        Set **Attribute name** to **email**.
      </Step>

      <Step title="Set User Attribute">
        Set **User attribute** to **User Principal Name (UPN)**.

        <Frame>
          <img src="https://mintcdn.com/iru/Qq59wQ8jCPy0XJe9/assets/media/images/iru-support-google-saml_11-27-41.png?fit=max&auto=format&n=Qq59wQ8jCPy0XJe9&q=85&s=4cbca1474cdb1bacd0395dede4186ac8" alt="Iru Endpoint User attribute set to User Principal Name UPN" width="1734" height="484" data-path="assets/media/images/iru-support-google-saml_11-27-41.png" />
        </Frame>
      </Step>

      <Step title="Identify Provider">
        Scroll down to **Identity provider** section.
      </Step>

      <Step title="Add IdP Entity ID">
        Paste the **Entity ID** you copied from Google Workspace into the **IdP Entity ID** field.
      </Step>

      <Step title="Add IdP Single Sign-in URL">
        Paste in the **IdP Single Sign-in URL** you copied from Google Workspace.
      </Step>

      <Step title="Upload Certificate">
        Upload the certificate you downloaded from Google Workspace.

        <Frame>
          <img src="https://mintcdn.com/iru/Qq59wQ8jCPy0XJe9/assets/media/images/iru-support-google-saml_11-35-42.png?fit=max&auto=format&n=Qq59wQ8jCPy0XJe9&q=85&s=49298bf3e5d179e6a1b35e0847154f73" alt="Upload certificate from Google Workspace in Iru Endpoint" width="1994" height="760" data-path="assets/media/images/iru-support-google-saml_11-35-42.png" />
        </Frame>
      </Step>

      <Step title="Request Configuration">
        Scroll down to **Request Configuration** section.
      </Step>

      <Step title="Set Request Binding">
        Set the **Request Binding** to **HTTP-POST**.
      </Step>

      <Step title="Set Signature Request Algorithm">
        Ensure that the **Request Signature Algorithm** is set to **RSA-SHA256**.
      </Step>

      <Step title="Set Request Digest Algorithm">
        Ensure that **Sign Request Algorithm Digest** is set to **SHA256**.
      </Step>

      <Step title="Enable Sign SAML Authentication Request">
        Ensure that **Sign SAML Authentication Request** is enabled.

        <Frame>
          <img src="https://mintcdn.com/iru/Qq59wQ8jCPy0XJe9/assets/media/images/iru-support-google-saml_11-41-47.png?fit=max&auto=format&n=Qq59wQ8jCPy0XJe9&q=85&s=7d781df5dfb962542c6dd819292a1b2c" alt="Sign SAML Authentication Request enabled in Request Configuration" width="2018" height="538" data-path="assets/media/images/iru-support-google-saml_11-41-47.png" />
        </Frame>
      </Step>

      <Step title="Response Validation">
        Scroll down to **Response Validation** section.
      </Step>

      <Step title="Set Response Signature Verification">
        Set **Response Signature Verification** to **Response**.
      </Step>

      <Step title="Set Destination">
        Leave the optional **Destination** blank.
      </Step>

      <Step title="Set Allowed Signature Algorithm">
        Set **Allowed Signature Algorithm** to **RSA-SHA256**.
      </Step>

      <Step title="Set Allowed Digest Algorithm">
        Set **Allowed Digest Algorithm** to **SHA256**.
      </Step>

      <Step title="Save Configuration">
        Click **Save**.

        <Frame>
          <img src="https://mintcdn.com/iru/Qq59wQ8jCPy0XJe9/assets/media/images/iru-support-google-saml_11-46-41.png?fit=max&auto=format&n=Qq59wQ8jCPy0XJe9&q=85&s=2d685d24dd8af4065224a6e27705dfe8" alt="Save button for SAML configuration in Iru Endpoint" width="2006" height="634" data-path="assets/media/images/iru-support-google-saml_11-46-41.png" />
        </Frame>
      </Step>
    </Steps>

    ### Allow for Tenant Authentication

    Once you have configured the SAML connection in Iru Endpoint and your identity provider, you can allow its use for tenant authentication. For step-by-step instructions, please refer to the **Allowing Tenant Authentication and Managing Connections** section in our [Single Sign-on support article](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on).

    ### Limit Authentication to Domain

    When configuring the SAML connection, you can optionally limit authentication to one or more domains. This can be useful when the SSO connection could authenticate to multiple domains. You can limit the authentication to your Iru tenant to a subset of the available domains.

    ### Enforcing Single Sign-On

    Once you have configured at least one Single Sign-on connection, you can disable Passkey, Google Social, and Microsoft Social connections. Disabling these connections will disable the ability for Iru Endpoint administrators in your tenant to authenticate via those methods. Please refer to our [Single Sign-on support article](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on) for step-by-step instructions.

    ### Testing the Integration

    <Steps>
      <Step title="Add User to Admin Team">
        Add a user to the **Admin Team** in Iru Endpoint by clicking **New User**.
      </Step>

      <Step title="Fill User Information">
        Fill in all of the corresponding user information. This user must exist in Google Workspace and must be assigned to the Iru Endpoint SSO app in your Google Workspace tenant.
      </Step>

      <Step title="Submit User">
        Click **Submit**.
      </Step>

      <Step title="Close Invite Window">
        Once the invite is submitted, close the Invite User window.
      </Step>

      <Step title="Refresh Access Page">
        Refresh the Access page in Iru Endpoint. You should see the user you just added.
      </Step>

      <Step title="Test SSO Login">
        Check the user's email to accept the invitation and log into Iru Endpoint with the new SAML SSO connection.
      </Step>
    </Steps>
  </Tab>

  <Tab title="Google Workspace Configuration">
    <Note>
      Before starting the Google Workspace configuration, complete [**Setting Up the SAML Connection**](#setting-up-the-saml-connection) in the [**Iru Web App Configuration**](#iru-web-app-configuration) tab to get the Service Provider Entity ID and ACS URL. You'll need these values to configure the Google Workspace application.
    </Note>

    ### Configuring Google Workspace Application

    <Steps>
      <Step title="Access Google Admin Console">
        In a new browser tab, log in to [admin.google.com](https://admin.google.com) with a Google Workspace admin account.
      </Step>

      <Step title="Open Menu">
        Click the menu symbol at the top left.
      </Step>

      <Step title="Navigate to Apps">
        Select **Apps**.
      </Step>

      <Step title="Select Web and Mobile Apps">
        Select **Web and mobile apps**.

        <Frame>
          <img src="https://mintcdn.com/iru/Qq59wQ8jCPy0XJe9/assets/media/images/iru-support-google-saml_13-01-38.png?fit=max&auto=format&n=Qq59wQ8jCPy0XJe9&q=85&s=b0358ffb20054e99d6234e69d585e840" alt="Google Admin Console Apps Web and mobile apps" width="3618" height="1812" data-path="assets/media/images/iru-support-google-saml_13-01-38.png" />
        </Frame>
      </Step>

      <Step title="Add New App">
        Click the **Add app** dropdown.
      </Step>

      <Step title="Select Custom SAML App">
        Select **Add custom SAML app**.

        <Frame>
          <img src="https://mintcdn.com/iru/Qq59wQ8jCPy0XJe9/assets/media/images/iru-support-google-saml_13-09-57.png?fit=max&auto=format&n=Qq59wQ8jCPy0XJe9&q=85&s=2a08d502ec6a6eae2ec4981dc8aa0844" alt="Google Workspace Add app dropdown with Add custom SAML app" width="3618" height="1720" data-path="assets/media/images/iru-support-google-saml_13-09-57.png" />
        </Frame>
      </Step>

      <Step title="Configure App Details">
        On the App details page:

        1. Set an **App name**.
        2. Optionally, add a **Description**.
        3. Upload an optional **App icon**.
        4. Click **Continue**.

        <Frame>
          <img src="https://mintcdn.com/iru/Qq59wQ8jCPy0XJe9/assets/media/images/iru-support-google-saml_13-15-43.png?fit=max&auto=format&n=Qq59wQ8jCPy0XJe9&q=85&s=95aee60e7567459733a0fb7c0c3e1347" alt="Google Workspace SAML app details with App name Description and Continue" width="1992" height="1766" data-path="assets/media/images/iru-support-google-saml_13-15-43.png" />
        </Frame>
      </Step>

      <Step title="Copy Google Identity Provider Details">
        On the Google Identity Provider Details page, use **Option 2: Copy the SSO URL, entity ID, and certificate.**

        1. Copy the **SSO URL** and save it to a text document for later use. You'll need this to complete the Iru Web App Configuration.
        2. Copy the **Entity ID** and save it to a text document for later use. You'll paste this into the **IdP Entity ID** field in Iru Endpoint.
        3. Download the **Certificate** and save it. You'll need this to complete the Iru Web App Configuration.
        4. Click **Continue**.

        <Frame>
          <img src="https://mintcdn.com/iru/Qq59wQ8jCPy0XJe9/assets/media/images/iru-support-google-saml_13-17-01.png?fit=max&auto=format&n=Qq59wQ8jCPy0XJe9&q=85&s=cbc64dbfb64fee7b87a431f4c7b43c3d" alt="Google Identity Provider Details SSO URL Entity ID and Certificate with Continue" width="1992" height="2192" data-path="assets/media/images/iru-support-google-saml_13-17-01.png" />
        </Frame>
      </Step>

      <Step title="Configure Service Provider Details">
        On the Service Provider Details page:

        1. In the ACS URL field, paste the **Iru Endpoint Assertion Consumer Service URL** you copied from the Iru Web App Configuration.
        2. Paste the Iru Endpoint Entity ID you copied from the Iru Web App Configuration in the **Entity ID** field.
        3. Ensure that the **Signed response** option is checked.
        4. Set the Name ID Format to **EMAIL**.
        5. For NameID, make sure that **Basic Information > Primary email** is selected.
        6. Click **CONTINUE**.

        <Frame>
          <img src="https://mintcdn.com/iru/Qq59wQ8jCPy0XJe9/assets/media/images/iru-support-google-saml_13-21-59.png?fit=max&auto=format&n=Qq59wQ8jCPy0XJe9&q=85&s=9b5f11a0cd4ad2b0bdd90bb8d81f53a8" alt="Google Service Provider Details ACS URL Entity ID Signed response and CONTINUE" width="1992" height="1932" data-path="assets/media/images/iru-support-google-saml_13-21-59.png" />
        </Frame>
      </Step>

      <Step title="Configure Attribute Mapping">
        On the Attribute Mapping page:

        1. Click **ADD MAPPING**.
        2. Select the **Primary email** attribute in the **Basic information** dropdown menu.
        3. Enter **email** in the **App attributes** field.
        4. Click **Finish**.

        <Frame>
          <img src="https://mintcdn.com/iru/Qq59wQ8jCPy0XJe9/assets/media/images/iru-support-google-saml_13-25-56.png?fit=max&auto=format&n=Qq59wQ8jCPy0XJe9&q=85&s=f0ca3c14befa7d32501960a139150471" alt="Google Attribute Mapping ADD MAPPING Primary email and Finish" width="1992" height="1744" data-path="assets/media/images/iru-support-google-saml_13-25-56.png" />
        </Frame>
      </Step>

      <Step title="Configure User Access">
        On the resulting app page, check under User Access to ensure that the service is turned on and that either a user group or organizational unit is selected.

        1. If it displays **OFF for everyone**, click on the disclosure triangle in the user access panel to assign a user group or organizational unit to the app.

        <Frame>
          <img src="https://mintcdn.com/iru/Qq59wQ8jCPy0XJe9/assets/media/images/iru-support-google-saml_13-29-40.png?fit=max&auto=format&n=Qq59wQ8jCPy0XJe9&q=85&s=1cc17e959f7d8b7e217a08af4d9faaa5" alt="Google Workspace app User Access disclosure to assign group or OU" width="2460" height="1326" data-path="assets/media/images/iru-support-google-saml_13-29-40.png" />
        </Frame>

        2. Optionally, please select a group or organizational unit to enable the service (by default, it will display all organizational units).
        3. Set service status to **ON for everyone**.
        4. Click **Save**.

        <Frame>
          <img src="https://mintcdn.com/iru/Qq59wQ8jCPy0XJe9/assets/media/images/iru-support-google-saml_13-33-58.png?fit=max&auto=format&n=Qq59wQ8jCPy0XJe9&q=85&s=7be7cae58eff5ea8d206a46b4c610dbd" alt="Google Workspace User Access ON for everyone and Save" width="2398" height="1348" data-path="assets/media/images/iru-support-google-saml_13-33-58.png" />
        </Frame>
      </Step>
    </Steps>

    <Note>
      The Required Claim Attributes section of the [SAML-based Single Sign-on](/en/endpoint/integrations/single-sign-on-integrations/saml-based-single-sign-on) knowledge base article provides more about Iru Endpoint attribute mappings.
    </Note>

    <Note>
      After completing the Google Workspace configuration, return to the **Iru Web App Configuration** tab to finish setting up the SAML connection using the SSO URL, Entity ID, and certificate you copied from Google Workspace.
    </Note>
  </Tab>
</Tabs>

## Considerations

**Security**: Ensure that your Google Workspace tenant has appropriate security policies configured for SAML authentication.

**User Management**: Users must exist in both Google Workspace and Iru Endpoint to successfully authenticate via SSO.

**Testing**: Always test the SSO integration with a small group of users before rolling out to your entire organization.

**Attribute Mapping**: Proper attribute mapping is crucial for successful user authentication and profile synchronization.
